Critical severity9.8CISA KEVNVD Advisory· Published Jan 28, 2026· Updated Jun 17, 2026
CVE-2025-40551
CVE-2025-40551
Description
SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:solarwinds:web_help_desk:*:*:*:*:*:*:*:*range: <2026.1
- (no CPE)range: 12.8.8 HF1 and below
Patches
Vulnerability mechanics
References
3- www.solarwinds.com/trust-center/security-advisories/CVE-2025-40551nvdVendor Advisory
- documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htmnvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.